Nintendo switch users can bypass realms security
Person A (in my household) owns a bedrock Realm and plays via XBox. They have invited Person B into that Realm. Person B, in a different household, is playing on Nintendo Switch. Person C lives in the same household as Person B and is not invited into the Realm but they are actually able to enter the Realm. As far as I can tell, this happens when Person B and C are playing locally on their Switch and when Person B joins the Realm then Person C can sneak in to the Realm too irrespective of the fact that they are not on the invite list. Person A has no way of preventing Person C from accessing the Realm.
Created Issue:
Nintendo switch users can bypass realms security
Person A (in my household) owns a bedrock Realm and plays via XBox. They have invited Person B into that Realm. Person B, in a different household, is playing on Nintendo Switch. Person C lives in the same household as Person B and is not invited into the Realm but they are actually able to enter the Realm. As far as I can tell, this happens when Person B and C are playing locally on their Switch and when Person B joins the Realm then Person C can sneak in to the Realm too irrespective of the fact that they are not on the invite list. Person A has no way of preventing Person C from accessing the Realm.
Pinned a comment to REALMS-11966 but there appears to be no way for me to transition it back to open.
Requests to reopen issues do not belong on the bug tracker, they belong either in the Mojira Discord or the Mojira subreddit. Also, just because a report was resolved does not mean that your issue was fixed. Please read the Bug Tracker Guidelines on how to properly use the bug tracker and what different Resolutions mean. However, regarding REALMS-11966 specifically, its resolution is Works As Intended, meaning that the behavior described in the report is not a bug and won't be fixed.
As for the comment you left on the report:
Clear and unambiguous documentation explaining this behaviour to the parents of children who expect a safe environment for their children to play in.
This belongs in a separate report in the appropriate project (if the official documentation is listed on a Mojang-owned website, then it belongs in the WEB project, not REALMS).
Fix the security vulnerability that is already known to you.
Per [Mojang] DLon King's comment:
While we understand that bypassing the allowlist is possible via split screen, that is as designed currently. Changing this would be a feature request.
Feature requests do not belong on the bug tracker. For feature requests and/or suggestions, please visit The Minecraft Feedback Site or visit the Minecraft Feedback Discord server.
Quick Links:
📓 Bug Tracker Guidelines – 💬 Community Support – 📧 Mojang Support (Technical Issues) – 📧 Microsoft Support (Account Issues)
📓 Project Summary – ✍️ Feedback and Suggestions – 📖 Game Wiki – 📖 FAQs
We do not have enough information to reproduce this issue.
Please include the following information to help us understand your problem:
Please also attach any needed commands, datapacks, resourcepacks, screenshots, videos, or worlds needed to help reproduce this issue.
Refer to the Bug Tracker Guidelines for more information about how to write helpful bug reports. Bug reports with insufficient information may be closed as Incomplete.
This issue is being temporarily resolved as Awaiting Response. Once the requested information has been delivered, the report will be reopened automatically.
Quick Links:
📓 Bug Tracker Guidelines – 💬 Community Support – 📧 Mojang Support (Technical Issues) – 📧 Microsoft Support (Account Issues)
📓 Project Summary – ✍️ Feedback and Suggestions – 📖 Game Wiki – 📖 FAQs
This repro requires several users and devices so first I will specify those pre-requisites, then add the steps to reproduce. This repro is anonymised as the people involved are children, as such no personal details will be included in this issue.
Prerequisites
Steps to Reproduce:
Observed Results:
Person C successfully enters the Realm.
Expected Results:
Person C should not be able to enter the Realm because they have not been invited into the Realm nor do they have a shared link.
While we understand that bypassing the allowlist is possible via split screen, that is as designed currently. Changing this would be a feature request.
If this were "as designed" it would be clearly documented. Your official documentation on how to add people into realms makes no statement of the fact that such people can enter a realm without the realm owners consent. Neither does your documentation on blocking and removing players state that a realm owner is powerless to prevent such people from entering their realm. It is therefore a security vulnerability.
There are two resolution paths:
You as the product owners have the right to choose which resolution path to take but you must take one of them in order for this issue to be considered resolved.